index.php in Tritanium Bulletin Board 1.2.3 allows remote attackers to read and reply to arbitrary messages by modifying the thread_id, forum_id, and sid parameters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tritanium_bulletin_board | Tritanium_scripts | 0.993_beta | 0.993_beta |
Tritanium_bulletin_board | Tritanium_scripts | 0.994_beta | 0.994_beta |
Tritanium_bulletin_board | Tritanium_scripts | 0.999_beta | 0.999_beta |
Tritanium_bulletin_board | Tritanium_scripts | 1.0_beta | 1.0_beta |
Tritanium_bulletin_board | Tritanium_scripts | 1.1_final | 1.1_final |
Tritanium_bulletin_board | Tritanium_scripts | 1.2 | 1.2 |
Tritanium_bulletin_board | Tritanium_scripts | 1.2.1 | 1.2.1 |
Tritanium_bulletin_board | Tritanium_scripts | 1.2.2 | 1.2.2 |
Tritanium_bulletin_board | Tritanium_scripts | 1.2.3 | 1.2.3 |